Skip to content

Latest commit

 

History

History
1755 lines (1287 loc) · 20.8 KB

File metadata and controls

1755 lines (1287 loc) · 20.8 KB

Title

Registration bypass using OAuth logical bug

URL

https://hackerone.com/reports/64946

Severity score

null

Reporter

paramdham

Bounty paid

$40


Title

X-Frame-Options

URL

https://hackerone.com/reports/237071

Severity score

null

Reporter

dark_heaven

Bounty paid

null


Title

Clickjacking

URL

https://hackerone.com/reports/21110

Severity score

null

Reporter

techintheprovince

Bounty paid

$50


Title

Clickjacking in the admin page

URL

https://hackerone.com/reports/728004

Severity score

null

Reporter

ant_pyne

Bounty paid

null


Title

https://admin.corp.cuvva.co/ is vulnerable to Clickjacking attacks due to missing X-Frame-Options

URL

https://hackerone.com/reports/231434

Severity score

null

Reporter

shepard

Bounty paid

null


Title

Clickjacking in Legalrobot app

URL

https://hackerone.com/reports/270454

Severity score

null

Reporter

9it0wl

Bounty paid

null


Title

Clickjacking irclogs.wordpress.org

URL

https://hackerone.com/reports/267075

Severity score

null

Reporter

sameull

Bounty paid

null


Title

User can be fooled to Bookmark any restaurant by clickjacking

URL

https://hackerone.com/reports/228295

Severity score

null

Reporter

na5ne3t

Bounty paid

null


Title

RTLO char allowed in chat

URL

https://hackerone.com/reports/196222

Severity score

null

Reporter

kontez

Bounty paid

$250


Title

URL is vulnerable to clickjacking

URL

https://hackerone.com/reports/337219

Severity score

null

Reporter

hacker_one_one

Bounty paid

null


Title

aspen | clickjacking

URL

https://hackerone.com/reports/272387

Severity score

null

Reporter

vilen07

Bounty paid

null


Title

UI Redressing on Embedded Charts

URL

https://hackerone.com/reports/244697

Severity score

null

Reporter

mr_r3boot

Bounty paid

null


Title

Bypass CSP frame-ancestors at olx.co.za, olx.com.gh

URL

https://hackerone.com/reports/371980

Severity score

null

Reporter

b9b86c2fc8409c628fb3de6

Bounty paid

null


Title

Clickjacking on donation page

URL

https://hackerone.com/reports/921709

Severity score

null

Reporter

b0d8e6c576cada9bb87be7b

Bounty paid

$50


Title

Clickjacking

URL

https://hackerone.com/reports/200419

Severity score

6.1

Reporter

b1b62e8d81ce1e3993ad913

Bounty paid

null


Title

frame injection on bittorrent.com

URL

https://hackerone.com/reports/846430

Severity score

null

Reporter

aslanemre

Bounty paid

null


Title

clickjacking to Semrush auth login

URL

https://hackerone.com/reports/318295

Severity score

null

Reporter

karrrtik

Bounty paid

null


Title

Clickjacking : https://partners.cloudflare.com/

URL

https://hackerone.com/reports/106362

Severity score

null

Reporter

xsserboiii

Bounty paid

null


Title

Certificate warnings and similar UI elements in Web protection of Anti-Virus products family are susceptible to clickjacking

URL

https://hackerone.com/reports/463695

Severity score

null

Reporter

palant

Bounty paid

null


Title

UI Redressing ( ClickJacking ) Issue on Information submit form

URL

https://hackerone.com/reports/163753

Severity score

null

Reporter

khizer47

Bounty paid

null


Title

Clickjacking on https://download.nextcloud.com

URL

https://hackerone.com/reports/658011

Severity score

null

Reporter

bibek1

Bounty paid

null


Title

Crafted frame injection leading to form-based UI redressing.

URL

https://hackerone.com/reports/291683

Severity score

null

Reporter

edoverflow

Bounty paid

$100


Title

URL is vulnerable to clickjacking https://app.passit.io/

URL

https://hackerone.com/reports/530008

Severity score

null

Reporter

whitehacker18

Bounty paid

null


Title

Clickjacking on cas.acronis.com login page

URL

https://hackerone.com/reports/971234

Severity score

null

Reporter

dgirlwhohacks

Bounty paid

null


Title

Cross-site Scripting (XSS) - Stored in RDoc wiki pages

URL

https://hackerone.com/reports/662287

Severity score

null

Reporter

vakzz

Bounty paid

$3,500


Title

ClickJacking in editing business name

URL

https://hackerone.com/reports/227837

Severity score

null

Reporter

mohammad_obaid

Bounty paid

null


Title

clickjacking at http://mailboxes.legalrobot-uat.com/

URL

https://hackerone.com/reports/165542

Severity score

null

Reporter

amir0ezat

Bounty paid

null


Title

UI Redressing (Clickjacking) vulnerability

URL

https://hackerone.com/reports/776932

Severity score

null

Reporter

p1k4chu0

Bounty paid

null


Title

Clickjacking on https://www.goodhire.com/api

URL

https://hackerone.com/reports/298028

Severity score

null

Reporter

tolo7010

Bounty paid

null


Title

Click jacking in delete image of user in Yelp

URL

https://hackerone.com/reports/201848

Severity score

null

Reporter

mohamedsherif

Bounty paid

null


Title

Bypassing X-frame options

URL

https://hackerone.com/reports/283951

Severity score

null

Reporter

haxorgirl

Bounty paid

null


Title

Frameset(Frame) html tag is allowed in html editor.(can lead to clickjacking)

URL

https://hackerone.com/reports/285609

Severity score

null

Reporter

na5ne3t

Bounty paid

null


Title

Twitter Periscope Clickjacking Vulnerability

URL

https://hackerone.com/reports/591432

Severity score

null

Reporter

eo420

Bounty paid

$1,120


Title

nginx server vulnerable

URL

https://hackerone.com/reports/137230

Severity score

null

Reporter

thalaivarsubu

Bounty paid

null


Title

Clickjacking in [exchangemarketplace.com]

URL

https://hackerone.com/reports/658217

Severity score

null

Reporter

eissen5c

Bounty paid

null


Title

ClickJacking

URL

https://hackerone.com/reports/179839

Severity score

null

Reporter

jessepinkman

Bounty paid

null


Title

ClickJacking

URL

https://hackerone.com/reports/183127

Severity score

null

Reporter

blablaa

Bounty paid

null


Title

Attack User Privacy Settings - X-Frame-Options missing on m.imgur.com/user/username/settings

URL

https://hackerone.com/reports/103178

Severity score

null

Reporter

kasser

Bounty paid

null


Title

Clickjacking wordcamp.org

URL

https://hackerone.com/reports/230581

Severity score

null

Reporter

hasanexpert

Bounty paid

null


Title

Nextcloud Clickjacking Vulnerability

URL

https://hackerone.com/reports/710996

Severity score

null

Reporter

try_4_hack

Bounty paid

null


Title

Clickjacking Full account takeover and editing the personal information at [account.my.com]

URL

https://hackerone.com/reports/261652

Severity score

null

Reporter

t-pwn

Bounty paid

null


Title

Clickjacking

URL

https://hackerone.com/reports/8724

Severity score

null

Reporter

ma120320

Bounty paid

$150


Title

Clickjacking login page of http://book.zomato.com/

URL

https://hackerone.com/reports/146948

Severity score

null

Reporter

benoculars

Bounty paid

null


Title

Missing security headers, possible clickjacking

URL

https://hackerone.com/reports/64645

Severity score

null

Reporter

paramdham

Bounty paid

$20


Title

Clickjacking In https://demo.nextcloud.com

URL

https://hackerone.com/reports/222762

Severity score

null

Reporter

xsszeeshan

Bounty paid

null


Title

Clickjacking on my.stripo.email for MailChimp credentials

URL

https://hackerone.com/reports/737625

Severity score

null

Reporter

jasongardner

Bounty paid

null


Title

[api.tumblr.com] Exploiting clickjacking vulnerability to trigger self DOM-based XSS

URL

https://hackerone.com/reports/953579

Severity score

null

Reporter

fuzzme

Bounty paid

$150


Title

Settings page in https://support.my.com is vulnerable to clickjacking

URL

https://hackerone.com/reports/667400

Severity score

0

Reporter

obayda

Bounty paid

null


Title

Single Sing On - Clickjacking

URL

https://hackerone.com/reports/299009

Severity score

null

Reporter

r0p3

Bounty paid

$150


Title

Possible clickjacking at shop.khanacademy.org

URL

https://hackerone.com/reports/6370

Severity score

null

Reporter

internetwache

Bounty paid

null


Title

Account takeover vulnerability by editor role privileged users/attackers via clickjacking

URL

https://hackerone.com/reports/388254

Severity score

null

Reporter

rewanth_cool

Bounty paid

null


Title

Clickjacking at https://staging.uzbey.com/

URL

https://hackerone.com/reports/17315

Severity score

null

Reporter

vineet

Bounty paid

null


Title

Clickjacking on Mixmax.com

URL

https://hackerone.com/reports/234713

Severity score

null

Reporter

mrr3boot

Bounty paid

null


Title

Clickjacking: X-Frame-Options header missing

URL

https://hackerone.com/reports/129650

Severity score

null

Reporter

white_hat_0003

Bounty paid

null


Title

RTLO character allowed in shared files

URL

https://hackerone.com/reports/229170

Severity score

null

Reporter

inhibitor181

Bounty paid

null


Title

ClickJacking on Debug

URL

https://hackerone.com/reports/225555

Severity score

null

Reporter

bf7e43565d8cf54de3bc5a7

Bounty paid

null


Title

Clickjacking Vulnerability via https://webagent.mail.ru leading to protection bypass for https://web.icq.com/ end point

URL

https://hackerone.com/reports/918923

Severity score

3.8

Reporter

jayesh25

Bounty paid

$150


Title

Improper markup sanitization.

URL

https://hackerone.com/reports/289823

Severity score

null

Reporter

edoverflow

Bounty paid

$150


Title

Clickjacking: X-Frame-Options header missing

URL

https://hackerone.com/reports/163646

Severity score

null

Reporter

vilen07

Bounty paid

null


Title

http://us.rd.yahoo.com/

URL

https://hackerone.com/reports/12035

Severity score

null

Reporter

rickgeex

Bounty paid

null


Title

Clickjacking in ops.cuvva.com

URL

https://hackerone.com/reports/583624

Severity score

null

Reporter

ph0b0s

Bounty paid

null


Title

Clickjacking Vulnerability on https://support.my.com/games/ticket/xxxx/

URL

https://hackerone.com/reports/357954

Severity score

null

Reporter

nullsaint

Bounty paid

null


Title

Gitlab.com is vulnerable to reverse tabnabbing via AsciiDoc links. (#3)

URL

https://hackerone.com/reports/213114

Severity score

5.4

Reporter

edoverflow

Bounty paid

null


Title

Vulnerable to clickjacking

URL

https://hackerone.com/reports/123782

Severity score

null

Reporter

trabajoduro

Bounty paid

null


Title

Make user buy items via clickjacking possibility

URL

https://hackerone.com/reports/471967

Severity score

3.8

Reporter

humanoidphantom

Bounty paid

$200


Title

Click jacking

URL

https://hackerone.com/reports/13550

Severity score

null

Reporter

dushyantsahu1

Bounty paid

null


Title

Found clickjacking vulnerability

URL

https://hackerone.com/reports/119828

Severity score

null

Reporter

9-d

Bounty paid

null


Title

clickjacking

URL

https://hackerone.com/reports/1207

Severity score

null

Reporter

adrianbelen

Bounty paid

null


Title

Clickjacking on https://download.nextcloud.com/

URL

https://hackerone.com/reports/662155

Severity score

null

Reporter

j4tayu

Bounty paid

null


Title

Sensitive Clickjacking on admin login page.

URL

https://hackerone.com/reports/389145

Severity score

null

Reporter

shakhawatpr99

Bounty paid

$100


Title

Modifying application settings via clickjacking on o2.mail.ru

URL

https://hackerone.com/reports/355774

Severity score

3.8

Reporter

zishanadthandar

Bounty paid

$150


Title

clickjacking on leaving group(flick)

URL

https://hackerone.com/reports/7745

Severity score

null

Reporter

adrianbelen

Bounty paid

null


Title

RTLO character in file names

URL

https://hackerone.com/reports/210354

Severity score

null

Reporter

inhibitor181

Bounty paid

$250


Title

URL is vulnerable to clickjacking

URL

https://hackerone.com/reports/712376

Severity score

null

Reporter

whitehacker18

Bounty paid

null


Title

Clickjacking mercantile.wordpress.org

URL

https://hackerone.com/reports/264125

Severity score

null

Reporter

villagelad

Bounty paid

null


Title

clickjacking on https://gratipay.com/on/npm/[text]

URL

https://hackerone.com/reports/267189

Severity score

null

Reporter

nihaddl

Bounty paid

null


Title

Following a User After Favoriting Actually Follows Another User (related to #95243)

URL

https://hackerone.com/reports/97510

Severity score

null

Reporter

ericr

Bounty paid

$280


Title

Missing X-Frame-Options header

URL

https://hackerone.com/reports/49888

Severity score

null

Reporter

abdul_r3hman

Bounty paid

null


Title

Improper markup sanitisation in Simplenote Android application.

URL

https://hackerone.com/reports/297547

Severity score

null

Reporter

edoverflow

Bounty paid

$300


Title

Stealing User emails by clickjacking cards.twitter.com/xxx/xxx

URL

https://hackerone.com/reports/154963

Severity score

null

Reporter

akhil-reni

Bounty paid

$1,120


Title

Highly wormable clickjacking in player card

URL

https://hackerone.com/reports/85624

Severity score

null

Reporter

filedescriptor

Bounty paid

$5,040


Title

Clickjacking vkpay

URL

https://hackerone.com/reports/374817

Severity score

4.3

Reporter

0x3c3e

Bounty paid

null


Title

Clickjacking at surveylink.yahoo.com

URL

https://hackerone.com/reports/3578

Severity score

null

Reporter

internetwache

Bounty paid

null


Title

Clickjacking Periscope.tv on Chrome

URL

https://hackerone.com/reports/198622

Severity score

null

Reporter

mishre

Bounty paid

$560


Title

Clickjacking: X-Frame-Options header missing

URL

https://hackerone.com/reports/27594

Severity score

null

Reporter

bigbear

Bounty paid

null


Title

Bypassing the Trusted Link Alert System

URL

https://hackerone.com/reports/384569

Severity score

5.7

Reporter

pipe-to-grep

Bounty paid

$150


Title

CJ vulnerability in subdomain

URL

https://hackerone.com/reports/140392

Severity score

null

Reporter

0x0ameer

Bounty paid

$50


Title

Clicjacking on Login panel

URL

https://hackerone.com/reports/8459

Severity score

null

Reporter

chandrakant

Bounty paid

null


Title

Clickjacking: X-Frame Header Missing

URL

https://hackerone.com/reports/168358

Severity score

null

Reporter

vaxo

Bounty paid

null


Title

ClickJacking on IMPORTANT Functions of Yelp

URL

https://hackerone.com/reports/305128

Severity score

3.5

Reporter

hk755a

Bounty paid

$500


Title

Clickjacking: Delete Account, Change privacy settings, Rate business, follow/unfollow (IE)

URL

https://hackerone.com/reports/338569

Severity score

null

Reporter

foobar7

Bounty paid

null


Title

AWS S3 website can't serve security headers, may allow clickjacking

URL

https://hackerone.com/reports/149572

Severity score

null

Reporter

null00null00

Bounty paid

$40


Title

Prepopulation of email address and name leaks information provided to other merchants

URL

https://hackerone.com/reports/316290

Severity score

null

Reporter

cablej

Bounty paid

$250


Title

Clickjacking at ylands.com

URL

https://hackerone.com/reports/405342

Severity score

null

Reporter

kryptomon

Bounty paid

$80


Title

ClickJacking

URL

https://hackerone.com/reports/7862

Severity score

null

Reporter

daksh

Bounty paid

null


Title

Clickjacking at https://www.mavenlink.com/ main website

URL

https://hackerone.com/reports/14631

Severity score

null

Reporter

vineet

Bounty paid

$50


Title

Click Jacking

URL

https://hackerone.com/reports/163888

Severity score

null

Reporter

muhaddix

Bounty paid

null


Title

Open URL Redirection

URL

https://hackerone.com/reports/4521

Severity score

null

Reporter

mafia

Bounty paid

null


Title

Click Jacking Nextcloud

URL

https://hackerone.com/reports/347782

Severity score

null

Reporter

enz0

Bounty paid

null


Title

Gitlab.com is vulnerable to reverse tabnabbing. (#2)

URL

https://hackerone.com/reports/212629

Severity score

5.4

Reporter

edoverflow

Bounty paid

null


Title

Site-wide clickjacking at IE11

URL

https://hackerone.com/reports/614947

Severity score

null

Reporter

skavans

Bounty paid

$500


Title

Viral Direct Message Clickjacking via link truncation leading to capture of both Google credentials & installation of malicious 3rd party Twitter App

URL

https://hackerone.com/reports/643274

Severity score

null

Reporter

slickrockweb

Bounty paid

$1,120


Title

Clickjacking on https://nextcloud.com/

URL

https://hackerone.com/reports/661768

Severity score

null

Reporter

j4tayu

Bounty paid

null


Title

Ошибка фильтрации

URL

https://hackerone.com/reports/34686

Severity score

null

Reporter

cyberunit

Bounty paid

$500


Title

Clickjacking @ Main Domain[www.yelp.com]

URL

https://hackerone.com/reports/197115

Severity score

null

Reporter

h4ck3r0ne

Bounty paid

null


Title

Clickjacking vulnerability in support-dashboard.corp.cuvva.co

URL

https://hackerone.com/reports/231694

Severity score

null

Reporter

d0rkerdevil

Bounty paid

null


Title

Bypass of the Clickjacking protection on Flickr using data URL in iframes

URL

https://hackerone.com/reports/7264

Severity score

null

Reporter

joserabal

Bounty paid

$250


Title

Modify account details by exploiting clickjacking vulnerability on refer.wordpress.com

URL

https://hackerone.com/reports/765355

Severity score

null

Reporter

theamanrawat

Bounty paid

$75


Title

Sandboxed iframes don't show confirmation screen

URL

https://hackerone.com/reports/54733

Severity score

null

Reporter

homakov

Bounty paid

$1,000


Title

Delete images of users with clickjacking in https://pw.mail.ru

URL

https://hackerone.com/reports/675614

Severity score

3.1

Reporter

chajer

Bounty paid

null


Title

Clickjacking - https://mercantile.wordpress.org/

URL

https://hackerone.com/reports/258283

Severity score

null

Reporter

giantfire

Bounty paid

null


Title

ClickJacking on http://au.launch.yahoo.com

URL

https://hackerone.com/reports/1229

Severity score

null

Reporter

p1k4chu

Bounty paid

null


Title

Clickjacking on authorized page https://wakatime.com/share/embed

URL

https://hackerone.com/reports/244967

Severity score

null

Reporter

silv3rpoision

Bounty paid

null


Title

Clickjacking - changing role

URL

https://hackerone.com/reports/7924

Severity score

null

Reporter

smiegles

Bounty paid

null


Title

Following links are vulnerable to clickjacking

URL

https://hackerone.com/reports/289246

Severity score

null

Reporter

karma1

Bounty paid

$150


Title

Clickjacking

URL

https://hackerone.com/reports/832593

Severity score

null

Reporter

hackerboy404

Bounty paid

null


Title

Clickjacking In jobs.wordpress.net

URL

https://hackerone.com/reports/223024

Severity score

null

Reporter

5ecurity5roker

Bounty paid

null